ESAs Call for Stronger Controls on Frontier AI ICT Risks
The European Supervisory Authorities - the EBA, EIOPA and ESMA - published a joint statement on 31 July 2026 calling for a cross-sector, risk-based supervisory approach to information and communications technology risks linked to frontier AI models.
The statement focuses on operational resilience. The ESAs said financial entities should strengthen governance and risk-management frameworks for cyber risks associated with frontier AI models, with emphasis on prevention, detection and management. ESMA also said the work links to ongoing and planned DORA oversight of critical ICT third-party providers.
For trading firms and brokers, the message is that AI tools are not only a productivity or client-service issue. If AI systems become part of research, surveillance, customer support, code generation, execution tooling or vendor workflows, supervisors may treat failures, abuse and dependencies as operational resilience risks.
The statement does not create a new trading rule by itself, but it gives national competent authorities a shared basis for supervisory dialogue. That makes it relevant for EU brokers, crypto-asset service providers, market-data vendors and platform providers using AI in customer-facing or operational workflows.
Why it matters
Traders increasingly rely on broker platforms, automated tools and AI-supported market interfaces. Stronger governance expectations could affect which AI features brokers release, how quickly they release them, and how much transparency clients receive when a tool influences account access, risk monitoring or trade support.
What to watch next
Watch for DORA supervisory activity around critical ICT third-party providers and for national regulators to ask brokers how frontier AI tools are tested, monitored and controlled. Platform outages or AI-driven security incidents could become a more visible regulatory topic.